Junglewise Threat Intelligence

CVE-2026-62527: Oracle Learning Management unauthorized data access in Import and Export

CVE-2026-62527 · Severity: medium · CVSS 6.3 · Published 2026-07-21

Technologies: Oracle Learning Management. Vendors: Oracle.

Executive brief

A vulnerability exists in the Import and Export component of Oracle Learning Management, a tool used by organizations to manage employee training and educational programs. An attacker with basic user credentials can exploit this flaw over the network to view, modify, or delete certain training data. This could lead to unauthorized changes in records or temporary disruptions to the learning management service.

Technical details

A vulnerability in the Oracle Learning Management product of Oracle E-Business Suite (specifically the Import and Export component) allows for unauthorized data manipulation. The flaw is easily exploitable by a low-privileged attacker with network access via HTTP. Successful exploitation enables an attacker to read, insert, update, or delete a subset of data within the application. Additionally, the vulnerability can be used to cause a partial denial of service (DoS). The issue affects versions 12.2.3 through 12.2.15 and was addressed in the July 2026 Oracle Critical Patch Update.

Affected products

  • Oracle Learning Management 12.2.3-12.2.15

Timeline

  • 2026-07-21: disclosed
  • 2026-07-21: advisory

References

Related threats